1.1 Compare and contrast various types of security controls

Domain 1: General Security Concepts

This objective tests whether you can classify security controls two ways at once: by category (technical, managerial, operational, physical) and by type (preventive, deterrent, detective, corrective, compensating, directive). The exam rarely asks for definitions in isolation. Instead, it gives you a concrete example — a bollard, an acceptable use policy, a SIEM alert, a guard checking badges — and asks you to place it on both axes. Practice by taking everyday controls and labeling them: a firewall is technical and preventive; log review is operational and detective; a warning sign is physical and deterrent. Pay special attention to compensating controls, which stand in when the primary control is not feasible, and directive controls, which tell people what to do rather than enforcing it. Candidates lose points when they assume a control has exactly one classification; many controls shift type depending on how the scenario says they are used.

What you must know

common pitfall · Candidates confuse deterrent controls with preventive ones — a deterrent discourages an attacker who could still proceed, while a preventive control actually blocks the action.

Try a sample question

A hospital runs a legacy imaging workstation whose operating system no longer receives security patches. Because the vendor application breaks on newer systems, the security team instead places the workstation on an isolated VLAN and restricts its traffic with strict firewall rules. Which type of security control has the team implemented?

  • A Corrective
  • B Compensating
  • C Deterrent
  • D Detective
Show answer & explanations
  • A Corrective controls restore systems or data after an incident has occurred, such as restoring from backup; here no incident has happened and nothing is being repaired.
  • B correct ·Correct. A compensating control provides an alternative safeguard when the primary control, patching the operating system, is not feasible; segmentation and firewall rules reduce the same risk through a different mechanism.
  • C Deterrent controls discourage attackers from attempting an action, like warning banners or visible cameras; network segmentation actually blocks traffic rather than merely discouraging attempts against the workstation.
  • D Detective controls identify and alert on events after or as they occur, such as log monitoring or an IDS; VLAN isolation prevents exposure rather than detecting malicious activity.

sample item — the full bank runs 450+ questions at exam difficulty

Is objective 1.1 your weak spot?

The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.

Check my readiness — free